CVE-2014-0098 is a denial-of-service vulnerability affecting Apache HTTP Server versions prior to 2.4.8, as well as various distributions from Canonical and Oracle. A remote attacker can trigger a segmentation fault and daemon crash by sending a crafted cookie that is improperly handled during truncation by the mod_log_config module. This vulnerability has a CVSS score of 5.0, indicating a network-based attack with low complexity and potential for partial availability impact. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0, < 2.2.27CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
>= 2.4.1, < 2.4.9CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
10.1.3.5.0CPE matchmatch criteria | cpe:2.3:a:oracle:http_server:10.1.3.5.0:*:*:*:*:*:*:* | ||
11.1.1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:http_server:11.1.1.7.0:*:*:*:*:*:*:* | ||
12.1.2.0CPE matchmatch criteria | cpe:2.3:a:oracle:http_server:12.1.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: mod_log_config does not properly handle logging certain cookies resulting in DoS
Mar 7, 2014Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project